[PR #1] Bump the npm_and_yarn group across 1 directory with 2 updates #1

Open
opened 2026-02-25 14:23:26 +03:00 by kerem · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/hermesthecat/reverse-memory-game-using-html-css-in-vanillajs/pull/1
Author: @dependabot[bot]
Created: 7/18/2025
Status: 🔄 Open

Base: mainHead: dependabot/npm_and_yarn/npm_and_yarn-0acb442647


📝 Commits (1)

  • 433c93a Bump the npm_and_yarn group across 1 directory with 2 updates

📊 Changes

2 files changed (+9 additions, -9 deletions)

View changed files

📝 package-lock.json (+8 -8)
📝 package.json (+1 -1)

📄 Description

Bumps the npm_and_yarn group with 2 updates in the / directory: on-headers and express-session.

Updates on-headers from 1.0.2 to 1.1.0

Release notes

Sourced from on-headers's releases.

1.1.0

Important

What's Changed

New Contributors

Full Changelog: https://github.com/jshttp/on-headers/compare/v1.0.2...v1.1.0

Changelog

Sourced from on-headers's changelog.

1.1.0 / 2025-07-17

Commits
  • 4b017af 1.1.0
  • b636f2d ♻️ refactor header array code
  • 3e2c2d4 ignore falsy header keys, matching node behavior
  • 172eb41 support duplicate headers
  • c6e3849 🔒️ fix array handling
  • 6893518 💚 update CI - add newer node versions
  • 56a345d add script to update known hashes
  • 175ab21 👷 add upstream change detection (#31)
  • ce0b2c8 ci: apply OSSF Scorecard security best practices (#20)
  • 1a38c54 fix: use ubuntu-latest as ci runner (#19)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by ulisesgascon, a new releaser for on-headers since your current version.


Updates express-session from 1.18.1 to 1.18.2

Release notes

Sourced from express-session's releases.

v1.18.2

What's Changed

New Contributors

Full Changelog: https://github.com/expressjs/session/compare/v1.18.1...v1.18.2

Changelog

Sourced from express-session's changelog.

1.18.2 / 2025-07-17

Commits
  • d10709f 🔖 v1.18.2 (#1070)
  • 5808783 deps: on-headers@1.1.0 (#1069)
  • b9fcad8 chore: fix typos (#1066)
  • a698c81 build(deps): bump coverallsapp/github-action from 1.2.5 to 2.3.6 (#1051)
  • ec1957b build(deps): bump actions/upload-artifact from 4.5.0 to 4.6.2 (#1052)
  • 2caff6a build(deps): bump actions/checkout from 4.1.1 to 4.2.2 (#1049)
  • 2633e88 build(deps): bump github/codeql-action from 3.24.7 to 3.28.18 (#1050)
  • 7e2c696 build(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.1 (#1048)
  • 92dd300 build(deps-dev): bump mocha from 10.2.0 to 10.8.2 (#1061)
  • 168271c fix(dependabot): do not update major versions
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/hermesthecat/reverse-memory-game-using-html-css-in-vanillajs/pull/1 **Author:** [@dependabot[bot]](https://github.com/apps/dependabot) **Created:** 7/18/2025 **Status:** 🔄 Open **Base:** `main` ← **Head:** `dependabot/npm_and_yarn/npm_and_yarn-0acb442647` --- ### 📝 Commits (1) - [`433c93a`](https://github.com/hermesthecat/reverse-memory-game-using-html-css-in-vanillajs/commit/433c93a7e59fd080d562ab535773a452f64a6c54) Bump the npm_and_yarn group across 1 directory with 2 updates ### 📊 Changes **2 files changed** (+9 additions, -9 deletions) <details> <summary>View changed files</summary> 📝 `package-lock.json` (+8 -8) 📝 `package.json` (+1 -1) </details> ### 📄 Description Bumps the npm_and_yarn group with 2 updates in the / directory: [on-headers](https://github.com/jshttp/on-headers) and [express-session](https://github.com/expressjs/session). Updates `on-headers` from 1.0.2 to 1.1.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/jshttp/on-headers/releases">on-headers's releases</a>.</em></p> <blockquote> <h2>1.1.0</h2> <h2>Important</h2> <ul> <li>Fix <a href="https://www.cve.org/CVERecord?id=CVE-2025-7339">CVE-2025-7339</a> (<a href="https://github.com/jshttp/on-headers/security/advisories/GHSA-76c9-3jph-rj3q">GHSA-76c9-3jph-rj3q</a>)</li> </ul> <h2>What's Changed</h2> <ul> <li>Migrate CI pipeline to GitHub actions by <a href="https://github.com/carpasse"><code>@​carpasse</code></a> in <a href="https://redirect.github.com/jshttp/on-headers/pull/12">jshttp/on-headers#12</a></li> <li>fix README.md badges by <a href="https://github.com/carpasse"><code>@​carpasse</code></a> in <a href="https://redirect.github.com/jshttp/on-headers/pull/13">jshttp/on-headers#13</a></li> <li>add OSSF scorecard action by <a href="https://github.com/carpasse"><code>@​carpasse</code></a> in <a href="https://redirect.github.com/jshttp/on-headers/pull/14">jshttp/on-headers#14</a></li> <li>fix: use <code>ubuntu-latest</code> as ci runner by <a href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a> in <a href="https://redirect.github.com/jshttp/on-headers/pull/19">jshttp/on-headers#19</a></li> <li>ci: apply OSSF Scorecard security best practices by <a href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a> in <a href="https://redirect.github.com/jshttp/on-headers/pull/20">jshttp/on-headers#20</a></li> <li>👷 add upstream change detection by <a href="https://github.com/ctcpip"><code>@​ctcpip</code></a> in <a href="https://redirect.github.com/jshttp/on-headers/pull/31">jshttp/on-headers#31</a></li> <li>✨ add script to update known hashes by <a href="https://github.com/ctcpip"><code>@​ctcpip</code></a> in <a href="https://redirect.github.com/jshttp/on-headers/pull/32">jshttp/on-headers#32</a></li> <li>💚 update CI - add newer node versions by <a href="https://github.com/ctcpip"><code>@​ctcpip</code></a> in <a href="https://redirect.github.com/jshttp/on-headers/pull/33">jshttp/on-headers#33</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/carpasse"><code>@​carpasse</code></a> made their first contribution in <a href="https://redirect.github.com/jshttp/on-headers/pull/12">jshttp/on-headers#12</a></li> <li><a href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a> made their first contribution in <a href="https://redirect.github.com/jshttp/on-headers/pull/19">jshttp/on-headers#19</a></li> <li><a href="https://github.com/ctcpip"><code>@​ctcpip</code></a> made their first contribution in <a href="https://redirect.github.com/jshttp/on-headers/pull/31">jshttp/on-headers#31</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/jshttp/on-headers/compare/v1.0.2...v1.1.0">https://github.com/jshttp/on-headers/compare/v1.0.2...v1.1.0</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/jshttp/on-headers/blob/master/HISTORY.md">on-headers's changelog</a>.</em></p> <blockquote> <h1>1.1.0 / 2025-07-17</h1> <ul> <li>Fix <a href="https://www.cve.org/CVERecord?id=CVE-2025-7339">CVE-2025-7339</a> (<a href="https://github.com/jshttp/on-headers/security/advisories/GHSA-76c9-3jph-rj3q">GHSA-76c9-3jph-rj3q</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/jshttp/on-headers/commit/4b017af88f5375bbdf3ad2ee732d2c122e4f52b0"><code>4b017af</code></a> 1.1.0</li> <li><a href="https://github.com/jshttp/on-headers/commit/b636f2d08e6c1e0a784b53a13cd61e05c09bb118"><code>b636f2d</code></a> ♻️ refactor header array code</li> <li><a href="https://github.com/jshttp/on-headers/commit/3e2c2d46c3e9592f6a1c3a3a1dbe622401f95d39"><code>3e2c2d4</code></a> ✨ ignore falsy header keys, matching node behavior</li> <li><a href="https://github.com/jshttp/on-headers/commit/172eb41b99a5a290b27a2c43fe602ca33aa1c8ce"><code>172eb41</code></a> ✨ support duplicate headers</li> <li><a href="https://github.com/jshttp/on-headers/commit/c6e384908c9c6127d18831d16ab0bd96e1231867"><code>c6e3849</code></a> 🔒️ fix array handling</li> <li><a href="https://github.com/jshttp/on-headers/commit/6893518341bb4e5363285df086b3158302d3b216"><code>6893518</code></a> 💚 update CI - add newer node versions</li> <li><a href="https://github.com/jshttp/on-headers/commit/56a345d82b51a0dcb8d09f061f87b1fd1dc4c01e"><code>56a345d</code></a> ✨ add script to update known hashes</li> <li><a href="https://github.com/jshttp/on-headers/commit/175ab217155d525371a5416ff059f895a3a532a6"><code>175ab21</code></a> 👷 add upstream change detection (<a href="https://redirect.github.com/jshttp/on-headers/issues/31">#31</a>)</li> <li><a href="https://github.com/jshttp/on-headers/commit/ce0b2c8fcd313d38d3534fb731050dc16e105bf6"><code>ce0b2c8</code></a> ci: apply OSSF Scorecard security best practices (<a href="https://redirect.github.com/jshttp/on-headers/issues/20">#20</a>)</li> <li><a href="https://github.com/jshttp/on-headers/commit/1a38c543e75cd06217b449531de10b1758e35299"><code>1a38c54</code></a> fix: use <code>ubuntu-latest</code> as ci runner (<a href="https://redirect.github.com/jshttp/on-headers/issues/19">#19</a>)</li> <li>Additional commits viewable in <a href="https://github.com/jshttp/on-headers/compare/v1.0.2...v1.1.0">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~ulisesgascon">ulisesgascon</a>, a new releaser for on-headers since your current version.</p> </details> <br /> Updates `express-session` from 1.18.1 to 1.18.2 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/expressjs/session/releases">express-session's releases</a>.</em></p> <blockquote> <h2>v1.18.2</h2> <h2>What's Changed</h2> <ul> <li>fix: Resolve test failure - Refresh server.crt with existing key extending expiry to Nov 21 03:28:10 2034 GMT by <a href="https://github.com/BaileyFirman"><code>@​BaileyFirman</code></a> in <a href="https://redirect.github.com/expressjs/session/pull/1003">expressjs/session#1003</a></li> <li>feat: gencert script to regenerate the test ssl certs by <a href="https://github.com/wesleytodd"><code>@​wesleytodd</code></a> in <a href="https://redirect.github.com/expressjs/session/pull/1015">expressjs/session#1015</a></li> <li>chore: upgrade scorecard workflow pinned action versions by <a href="https://github.com/carpasse"><code>@​carpasse</code></a> in <a href="https://redirect.github.com/expressjs/session/pull/1008">expressjs/session#1008</a></li> <li>ci: add CodeQL (SAST) by <a href="https://github.com/bjohansebas"><code>@​bjohansebas</code></a> in <a href="https://redirect.github.com/expressjs/session/pull/1005">expressjs/session#1005</a></li> <li>[StepSecurity] Apply security best practices by <a href="https://github.com/step-security-bot"><code>@​step-security-bot</code></a> in <a href="https://redirect.github.com/expressjs/session/pull/1047">expressjs/session#1047</a></li> <li>build(deps-dev): bump mocha from 10.2.0 to 10.8.2 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/expressjs/session/pull/1061">expressjs/session#1061</a></li> <li>build(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.1 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/expressjs/session/pull/1048">expressjs/session#1048</a></li> <li>build(deps): bump github/codeql-action from 3.24.7 to 3.28.18 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/expressjs/session/pull/1050">expressjs/session#1050</a></li> <li>build(deps): bump actions/checkout from 4.1.1 to 4.2.2 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/expressjs/session/pull/1049">expressjs/session#1049</a></li> <li>build(deps): bump actions/upload-artifact from 4.5.0 to 4.6.2 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/expressjs/session/pull/1052">expressjs/session#1052</a></li> <li>build(deps): bump coverallsapp/github-action from 1.2.5 to 2.3.6 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/expressjs/session/pull/1051">expressjs/session#1051</a></li> <li>chore: fix typos by <a href="https://github.com/noritaka1166"><code>@​noritaka1166</code></a> in <a href="https://redirect.github.com/expressjs/session/pull/1066">expressjs/session#1066</a></li> <li>deps: on-headers@1.1.0 by <a href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a> in <a href="https://redirect.github.com/expressjs/session/pull/1069">expressjs/session#1069</a></li> <li>🔖 v1.18.2 by <a href="https://github.com/ctcpip"><code>@​ctcpip</code></a> in <a href="https://redirect.github.com/expressjs/session/pull/1070">expressjs/session#1070</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/BaileyFirman"><code>@​BaileyFirman</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/session/pull/1003">expressjs/session#1003</a></li> <li><a href="https://github.com/wesleytodd"><code>@​wesleytodd</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/session/pull/1015">expressjs/session#1015</a></li> <li><a href="https://github.com/carpasse"><code>@​carpasse</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/session/pull/1008">expressjs/session#1008</a></li> <li><a href="https://github.com/step-security-bot"><code>@​step-security-bot</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/session/pull/1047">expressjs/session#1047</a></li> <li><a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] made their first contribution in <a href="https://redirect.github.com/expressjs/session/pull/1061">expressjs/session#1061</a></li> <li><a href="https://github.com/noritaka1166"><code>@​noritaka1166</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/session/pull/1066">expressjs/session#1066</a></li> <li><a href="https://github.com/ctcpip"><code>@​ctcpip</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/session/pull/1070">expressjs/session#1070</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/expressjs/session/compare/v1.18.1...v1.18.2">https://github.com/expressjs/session/compare/v1.18.1...v1.18.2</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/expressjs/session/blob/master/HISTORY.md">express-session's changelog</a>.</em></p> <blockquote> <h1>1.18.2 / 2025-07-17</h1> <ul> <li>deps: mocha@10.8.2</li> <li>deps: on-headers@~1.1.0 <ul> <li>Fix <a href="https://www.cve.org/CVERecord?id=CVE-2025-7339">CVE-2025-7339</a> (<a href="https://github.com/expressjs/on-headers/security/advisories/GHSA-76c9-3jph-rj3q">GHSA-76c9-3jph-rj3q</a>)</li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/expressjs/session/commit/d10709f319d1ff4069e1e552fc7f3ca27989e981"><code>d10709f</code></a> 🔖 v1.18.2 (<a href="https://redirect.github.com/expressjs/session/issues/1070">#1070</a>)</li> <li><a href="https://github.com/expressjs/session/commit/58087831a68787fb3c1ef8b821efb965225dc725"><code>5808783</code></a> deps: on-headers@1.1.0 (<a href="https://redirect.github.com/expressjs/session/issues/1069">#1069</a>)</li> <li><a href="https://github.com/expressjs/session/commit/b9fcad8a8bc8f1ac84809d81c569ffbcc6f9ef99"><code>b9fcad8</code></a> chore: fix typos (<a href="https://redirect.github.com/expressjs/session/issues/1066">#1066</a>)</li> <li><a href="https://github.com/expressjs/session/commit/a698c81f2ab950188cdbd7f30bb3a89fd68e2046"><code>a698c81</code></a> build(deps): bump coverallsapp/github-action from 1.2.5 to 2.3.6 (<a href="https://redirect.github.com/expressjs/session/issues/1051">#1051</a>)</li> <li><a href="https://github.com/expressjs/session/commit/ec1957b9bd169c582a00d83f5966f4c5fed9017d"><code>ec1957b</code></a> build(deps): bump actions/upload-artifact from 4.5.0 to 4.6.2 (<a href="https://redirect.github.com/expressjs/session/issues/1052">#1052</a>)</li> <li><a href="https://github.com/expressjs/session/commit/2caff6ae8976763841abbc8ed7b560cc5ebdf6cf"><code>2caff6a</code></a> build(deps): bump actions/checkout from 4.1.1 to 4.2.2 (<a href="https://redirect.github.com/expressjs/session/issues/1049">#1049</a>)</li> <li><a href="https://github.com/expressjs/session/commit/2633e88780e5655db44d11f917629942cb92628d"><code>2633e88</code></a> build(deps): bump github/codeql-action from 3.24.7 to 3.28.18 (<a href="https://redirect.github.com/expressjs/session/issues/1050">#1050</a>)</li> <li><a href="https://github.com/expressjs/session/commit/7e2c6964263b66d7fbdbd75d1c603413880fef64"><code>7e2c696</code></a> build(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.1 (<a href="https://redirect.github.com/expressjs/session/issues/1048">#1048</a>)</li> <li><a href="https://github.com/expressjs/session/commit/92dd3008e334eaa8466a431ae3c032b827b5816d"><code>92dd300</code></a> build(deps-dev): bump mocha from 10.2.0 to 10.8.2 (<a href="https://redirect.github.com/expressjs/session/issues/1061">#1061</a>)</li> <li><a href="https://github.com/expressjs/session/commit/168271c665519d7d9164f97873bd0eee88d9e6fb"><code>168271c</code></a> fix(dependabot): do not update major versions</li> <li>Additional commits viewable in <a href="https://github.com/expressjs/session/compare/v1.18.1...v1.18.2">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/hermesthecat/reverse-memory-game-using-html-css-in-vanillajs/network/alerts). </details> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
Sign in to join this conversation.
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
kerem/reverse-memory-game-using-html-css-in-vanillajs#1
No description provided.